Abstract:
The classical Bell & LaPadula (BLP) model, upon which the implementation of multilevel security (MLS) support in secure computer systems is based, is recognized as fundamental security axioms. With the development of a secure operating system, named RS-Linux, which is based on the Linux system, the practical significance of the abstract BLP security axioms in the implementation of a secure operating system is discussed. A new enforcement approach, named ABLP approach, for the BLP axioms is constructed theoretically. The correctness of the ABLP approach is proved. The ABLP approach, whose distinct characteristic is the adaptability of the current sensitivity label of a subject, mainly consists of three access control rules. It is an improvement on the basis of the ordinary enforcement approaches. Specifically, it overcomes the deficiencies of the ordinary enforcement approaches in subject label assignment and provides good flexibility for security decision.